Permission issue Classign #9


  • New
  • Defect
Open
Assigned to _ForgeUser6936550
  • _ForgeUser3513767 created this issue Dec 8, 2012

    Description of the Problem:

    Permission issues:
    Right now anyone can place classigns and activate/inactivate by default. It seems that your design is based upon everyone having full access to the plugin unless the permission is negative. To me this is bad design since it can lead to uncontrolled duping if you miss to remove a permission from a group who should not have it. Default should be deny on everything so that permissions have to be given to get the ability. (Yes even just using the sign)

    Also the ability to place the sign should be in the admin tree and not the user tree.

    I have also noticed another bug from local testing (private server) compared to the public server that I help run.
    On the local test server I have access to the the classsign commands but on the public one the commands are somehow blocked. This is most likely a conflict with another plugin. This is really worth testing from your side (If you have the time) I will also have a plugin tech from our server look at the source if I have your permission to do so.

  • _ForgeUser3513767 added the tags New Defect Dec 8, 2012
  • _ForgeUser6936550 posted a comment Dec 9, 2012

    By design, the activate/inactivate permissions are negative by default. You should only be able to do that if you are op, or you have the permission.

    And yes, I'm aware there may be command conflicts. That's why aliases exist. Read the front page for the list of aliases.


To post a comment, please login or register a new account.